CVE-2026-1767
published 2026-06-16CVE-2026-1767: A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit…
PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
0.25%
15.7th percentile
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | localsearch | < localsearch 3.8.2-12 (forky) | localsearch 3.8.2-12 (forky) |
| debian | tracker-miners | < localsearch 3.8.2-12 (forky) | localsearch 3.8.2-12 (forky) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tracker-miners vulnerabilities
vendor_ubuntu·2026-02-05
CVE-2026-1764 tracker-miners vulnerabilities
Title: tracker-miners vulnerabilities
Summary: tracker-miners could be made to crash or run programs as your login if it
opened a specially crafted file.
Fatih Çelik discovered that tracker-miners incorrectly handled certain
malformed MP3 files. An attacker could use this issue to cause
tracker-miners to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags
vendor_redhat·2026-02-02·CVSS 5.6
CVE-2026-1767 [MEDIUM] CWE-805 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags
localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
Statement: This vulnerability has MODERATE impact. A heap buffer overflow in the GNOME localsearch MP3 Extractor (`tracker-extract-mp3`). A specia
Debian
CVE-2026-1767: localsearch
vendor_debian·2026
CVE-2026-1767 CVE-2026-1767: localsearch
forky: resolved (fixed in 3.8.2-12)
sid: resolved (fixed in 3.8.2-12)
GHSA
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component.
ghsa_unreviewed·2026-06-16
CVE-2026-1767 [MEDIUM] CWE-805 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component.
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
OSV
CVE-2026-1767: [Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
osv·2026-02-03
CVE-2026-1767 CVE-2026-1767: [Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
[Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1767 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-1767 [MEDIUM] CVE-2026-1767 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1767 :
Linux Debian vulnerability analysis and mitigation
[Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
Source : NVD
Published February 3, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
tracker-miners
tracker-miners-lang
Sources
NVD
Debian 11 No Fix Added at: Feb 04, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Feb 04, 2026
Debian 14 Has Fix Added at: Feb 04, 2026
Echo No Fix Added at: Feb 04, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Feb 04, 2026
Ubuntu 22.04, 24.04, 25.10 Severity MEDIUM Has Fix
Bugzilla
CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
bugzilla·2026-02-03
CVE-2026-1764 [MEDIUM] CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Bug reports for this component on Red Hat Bugzilla are not actively monitored. Please consider reporting your issue directly to GNOME at https://gitlab.gnome.org/GNOME/ to improve the chances that your issue will be resolved. This issue should only be kept open if it:
1. Relates to Fedora packaging or integration with other Fedora components
2. Is required for Fedora release processes, such as blocker bugs and freeze exceptions
If this issue isn't needed fo
Bugzilla
CVE-2026-1767 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags
bugzilla·2026-02-02·CVSS 8.1
CVE-2026-1767 [HIGH] CVE-2026-1767 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags
CVE-2026-1767 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags
Vulnerability Report: Heap Buffer Overflow in GNOME localsearch MP3 Extractor
Project: https://gitlab.gnome.org/GNOME/localsearch
Component: tracker-extract-mp3
Vulnerability Type: Heap Buffer Overflow (Read)
Description
A heap buffer overflow vulnerability exists in the extract_performers_tags function of src/extractor/tracker-extract-mp3.c. A specially crafted MP3 file with malformed ID3 tags can cause the extractor to read beyond the allocated buffer when parsing performer tags, potentially leading to information disclosure or a crash (Denial of Service).
Root Cause Analysis
The vulnerability occurs in the l
2026-06-16
Published